📣 Send us your press release
Site updates every 15 minutes
Technology

Microsoft to Retire SMS/Voice MFA Due to AI Threats

Microsoft will discontinue SMS and voice-based multi-factor authentication (MFA) for Microsoft Entra users starting February 1, 2027. The company is mandating a shift to Passkeys to counter evolving AI-driven attacks.

22 July 2026
Microsoft to Retire SMS/Voice MFA Due to AI Threats
Image is an AI-generated illustration

Microsoft announced it will phase out multi-factor authentication (MFA) methods relying on SMS and voice calls for its Microsoft Entra service. Effective February 1, 2027, the company will require users to adopt Passkeys, citing the increasing threat of AI-powered cyberattacks.

The company stated that advancements in AI have significantly undermined the security of traditional authentication methods. Sophisticated, AI-enhanced phishing and social engineering attacks can now compromise credentials and bypass SMS or voice verification more rapidly. Consequently, these methods no longer meet Microsoft's security requirements.

Passkeys utilize public-key cryptography, where the private key remains on the user's device and is never transmitted. User identity is then verified through biometric authentication or a device PIN, offering a more robust security posture compared to traditional methods.

Microsoft explained that password-based authentication, including SMS one-time passcodes and voice-based verification, remains vulnerable to phishing, interception, and social engineering tactics. The move to Passkeys is positioned as a necessary upgrade to strengthen user account security against the evolving landscape of digital threats.

Original source: ithome.com